500-601 · Question #36
Which two interface types can be used to configure interface profiles for the border leaf ports of a Layer 3 external routed network? (Choose two)
The correct answer is A. Layer 3 subinterfaces E. Layer 3 extended GRE tunnel interfaces. In Cisco ACI, the interface profile for a border leaf's L3Out (Layer 3 external routed network) supports Layer 3 subinterfaces (A) - which allow VLAN-tagged routed connections on a single physical port - and Layer 3 extended GRE tunnel interfaces (E) - which enable encapsulated…
Question
Options
- ALayer 3 subinterfaces
- BLayer 2 ports with SPT-enaWed interfaces
- CLayer 4 - Layer 7 route peering interfaces
- DLayer 3 physical interfaces
- ELayer 3 extended GRE tunnel interfaces
How the community answered
(34 responses)- A82% (28)
- B6% (2)
- C9% (3)
- D3% (1)
Explanation
In Cisco ACI, the interface profile for a border leaf's L3Out (Layer 3 external routed network) supports Layer 3 subinterfaces (A) - which allow VLAN-tagged routed connections on a single physical port - and Layer 3 extended GRE tunnel interfaces (E) - which enable encapsulated overlay routing across underlay networks. These two interface types give operators the flexibility to either logically segment a physical link or tunnel routed traffic across an IP fabric.
Why the distractors are wrong:
- B (Layer 2 ports with STP-enabled interfaces) - STP is a switching/bridging construct; L3Out border leaf profiles require routed (Layer 3) interfaces, not Layer 2 switching.
- C (Layer 4–Layer 7 route peering interfaces) - L4–L7 is the service graph/service insertion domain in ACI; it does not define border leaf interface profiles for external routing.
- D (Layer 3 physical interfaces) - While physical routed ports exist in ACI, the question specifically targets the two interface profile types used in L3Out configuration, where subinterfaces and GRE tunnels are the defining options in this context.
Memory tip: Think "Sub and Tunnel" - ACI L3Out border leaf profiles let you go sub (subinterface for VLAN-tagged routing) or tunnel (GRE for overlay routing). If it's purely Layer 2 or belongs to the service chain (L4–L7), it's out of scope for L3Out interface profiles.
Topics
Community Discussion
No community discussion yet for this question.